Principal Security Engineer
Listed on 2026-07-11
-
IT/Tech
Cybersecurity, Systems Engineer
Jeppesen Fore Flight builds mission‑critical navigation and aviation data software used by pilots and operators worldwide.
As Principal Security Architect, you’ll own the technical security strategy across our enterprise IT and SaaS environments, partnering closely with engineering, infrastructure, product security, and compliance functions to protect pilot, operator, and aviation data. This senior individual contributor role has real authority—you set the architecture, drive adoption, and measure outcomes. You report into IT leadership while serving as the senior technical security voice across the enterprise and partnering with security peers within product engineering.
The role is hybrid in Denver, CO or Austin, TX, with remote candidates considered on a case‑by‑case basis.
- Define and continuously evolve the enterprise security architecture across identity, endpoint, network, cloud (AWS/Azure), and SaaS. Produce explicit threat models for each tier and translate them into prioritized engineering roadmaps.
- Design and oversee implementation of zero‑trust access, IAM/PAM, MFA, and privileged credential management—primarily using Okta and Entra .
Lead technical response to high‑severity incidents. Operate and mature EDR/XDR, SIEM, and DLP programs; drive post‑incident hardening with measurable outcomes.
Platform & Vendor Review- Evaluate and approve security designs for new platforms, SaaS integrations, infrastructure initiatives, and M&A activity before production deployment.
- Partner with GRC on SOC 2, ISO 27001, and aviation‑specific control requirements. Translate auditor findings and regulatory obligations into concrete engineering work—rather than policy binders.
- Mentor security and infrastructure engineers, raise the security bar in cross‑functional architecture reviews, and serve as a credible peer to product security engineering leaders.
- 10+ years in security engineering or architecture, including 3+ years as a principal architect or staff‑level IC with demonstrated enterprise ownership.
- Understanding of security across data centers, Azure, AWS, and hands‑on familiarity with IAM and VPC security.
- Proven experience with enterprise identity platforms (Okta, Entra /Azure AD) and modern detection tooling (EDR/XDR, SIEM, SOAR).
- Solid working knowledge of NIST CSF, ISO 27001, and SOC 2; familiarity with FAA/EASA, DoD, or CMMC contexts is a meaningful advantage.
- Track record of converting risk assessments and audit findings into shipped engineering improvements—rather than just recommendations.
- Strong communicator across audiences: comfortable whiteboarding with engineers and presenting risk posture to executives.
- Bachelor's in CS, engineering, or equivalent experience. CISSP, OSCP, or GIAC certifications are valued, not required.
- Experience in aviation, aerospace, defense, or other safety‑critical software environments where the cost of a security failure extends beyond data.
- Hands‑on experience integrating acquired companies onto a common enterprise security baseline—identity federation, endpoint standardization, and network segmentation.
- Familiarity with M&A security due diligence and post‑close integration planning.
- Medical, dental, vision insurance with employer‑paid health premiums.
- Open PTO policy.
- 401(k) with up to 10% company matching and immediate vesting.
- 12 weeks paid maternity leave.
- 4 weeks paid paternity leave.
- Flight training rewards.
Pay is based upon candidate experience and qualifications, as well as market and business considerations:
Summary Pay Range: $180,000–$220,000.
Jeppesen Fore Flight – EOE including Disability/Vets | Pay Transparency | E‑Verify Participant | Equal Opportunity Employer
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).